Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the "abb_uninstall_template" (both) and "jupiterx_core_cp_uninstall_template" (JupiterX Core Only) AJAX actions
| Software | From | Fixed in |
|---|---|---|
| artbees / jupiterx | - | 2.0.7.x |
| artbees / jupiter | - | 6.10.1.x |